bb86950632
enforcement - test: cover authenticated register, login, upload, list, and download flow - test: verify file API routes reject test identity header injection - test: verify file API routes reject invalid, expired, and malformed tokens - test: verify cross-user ownership isolation for all file CRUD operations - refactor: rename test-only header constant to clarify it is not used in production
2.0 KiB
2.0 KiB
Roadmap
v0
| Feature | Status | Notes |
|---|---|---|
| CLI config management | ✅ | Viper YAML + env + flags, typed Duration config |
| JWT authentication | ✅ | access + refresh tokens, refresh token in DB, app passkey support |
| Web API foundation | ✅ | WebApp composition, Gin router, graceful shutdown, GET /api/v1/version |
| File upload/download/manage APIs | 🛠 WIP | REST API via Gin |
| Admin endpoints | 🛠 WIP | user service boundary in place for superusers |
| WebDAV | 🛠 WIP | future v0 or v1 |
Implementation Tasks
Package-level implementation order (each task includes unit tests):
internal/config— Viper loader, config struct ✅internal/app— runtime dependency container ✅internal/model— domain types, error codes ✅internal/api— protocol-neutral error kind to REST response mapping ✅internal/auth— JWT utils ✅internal/storage— backend interface + local fs with staged upload promotioninternal/repository— interfaces + GORM/SQLite impl ✅internal/service— auth, file, admin services ✅internal/middleware— logger, cors, auth ✅ (auth done; principal boundary enforced)internal/handler— auth, account, file, admin handlers 🛠 (HTTP DTO mapping in place)internal/server— Gin router, route registration, graceful shutdown ✅cmd/serve.go,cmd/config.go,cmd/status.go✅ (serve done)- Integration tests 🛠 (authenticated register → login → upload → list → download route flow covered with a small file; file API authentication bypass, invalid token, and cross-user isolation boundaries covered)
- Architecture boundary tests ✅
Future
| Feature | Status | Notes |
|---|---|---|
| Image server | ⬜ plan | thumbnail generation |
| Pastebin & code snippets | ⬜ plan | in sharing context |
| S3 storage backend | ⬜ plan | new storage impl |
| Nextcloud-compatible API | ⬜ plan | new handler layer on existing services |